Virus Type: Malicious program, which installs other malicious programs out of its body Affected OS: Win NT-based
Size: 23 782 bytes
Packed by: -
When it starts, this virus substitutes system driver %WINDIR%\system32\drivers\ip6fw.sys with its own one (antivirus Dr.Web(R) detects it as BackDoor.Bulknet), it also secretly starts Internet Explorer and initiates mass-distribution of SYN_SENT packets on difined ip address. Occasionally sorts out ip addresses.
The virus also captures the following functions KiST:
ZwQuerySystemInformation
ZwClose
ZwReadFile
ZwQueryInformationFile
ZwOpenFile
Use utility TCPView in order to monitor network activity and complete Internet Explorer process.
For this in work window TCPView find record
<non-existent>:[PID] TCP <computer name> <remote address:port>
, then right-click and choose "End Process".
"Virus" driver should be deleted with updated scanner Dr.Web or with the help of free cure utility Dr.Web Cureit!